The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking that user registration is enabled prior to creating a user account through the register() function. This makes it possible for unauthenticated attackers to create user accounts on sites, even when user registration is disabled and plugin functionality is not activated.
History

Wed, 18 Sep 2024 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Inspireui
Inspireui mstore Api
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:inspireui:mstore_api:*:*:*:*:*:wordpress:*:*
Vendors & Products Inspireui
Inspireui mstore Api

Fri, 13 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Fluxbuilder
Fluxbuilder mstore Api
CPEs cpe:2.3:a:fluxbuilder:mstore_api:*:*:*:*:*:*:*:*
Vendors & Products Fluxbuilder
Fluxbuilder mstore Api
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Sep 2024 15:15:00 +0000

Type Values Removed Values Added
Description The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking that user registration is enabled prior to creating a user account through the register() function. This makes it possible for unauthenticated attackers to create user accounts on sites, even when user registration is disabled and plugin functionality is not activated.
Title MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-09-13T15:10:38.839Z

Updated: 2024-09-13T18:05:46.615Z

Reserved: 2024-08-28T17:34:13.175Z

Link: CVE-2024-8269

cve-icon Vulnrichment

Updated: 2024-09-13T18:04:58.289Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-13T15:15:17.050

Modified: 2024-09-18T15:20:44.553

Link: CVE-2024-8269

cve-icon Redhat

No data.